PkgRadar

npm · registry.npmjs.org

create-sitecore-jss

Credential File Packaged: package/dist/templates/angular-sxp/.env

Why PkgRadar flagged 22.12.2-canary.1

SeveritySignalEvidence
highCredential File Packagedpackage/dist/templates/angular-sxp/.env · package/dist/templates/angular-sxp/.env
highCredential File Packagedpackage/dist/templates/angular-xmcloud/.env · package/dist/templates/angular-xmcloud/.env
highCredential File Packagedpackage/dist/templates/angular/.env · package/dist/templates/angular/.env
highCredential File Packagedpackage/dist/templates/nextjs-xmcloud/.env · package/dist/templates/nextjs-xmcloud/.env
highCredential File Packagedpackage/dist/templates/nextjs/.env · package/dist/templates/nextjs/.env
highCredential File Packagedpackage/dist/templates/node-headless-ssr-experience-edge/.env · package/dist/templates/node-headless-ssr-experience-edge/.env
highCredential File Packagedpackage/dist/templates/node-headless-ssr-proxy/.env · package/dist/templates/node-headless-ssr-proxy/.env
highCredential File Packagedpackage/dist/templates/node-xmcloud-proxy/.env · package/dist/templates/node-xmcloud-proxy/.env
highCredential File Packagedpackage/dist/templates/react/.env · package/dist/templates/react/.env
highCredential File Packagedpackage/dist/templates/vue/.env · package/dist/templates/vue/.env

Scanned versions

VersionVerdictScoreScanned (UTC)
22.12.2-canary.1Review1002026-05-25
22.12.3Review1002026-05-25

Block this in CI

PkgRadar gates create-sitecore-jss (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]